BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

PrivateGPT

Privacy-first RAG app to ingest and query your documents using local or remote LLMs, fully offline-capable.

Website Source code

Category:
Document Analysis
Maintenance:
Actively developed (last commit 5 days ago)
Pricing:
Open Source
Open source:
Yes (Apache-2.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Self-hosted, Web, Library/SDK, CLI, Docker
AI providers (bring your own key):
OpenAI, Azure OpenAI, Google Gemini, Ollama, Custom / OpenAI-compatible
API key storage:
Configured by environment variable
Key risk level:
LOW
Trust score:
93/100

PrivateGPT is an Apache-2.0, source-available project (by Zylon) for ingesting documents and asking questions over them via RAG, with a focus on privacy and 100% offline operation. It exposes both a UI and an OpenAI-compatible API. Beyond fully local inference (Ollama, llama.cpp, vLLM, LocalAI), it supports bring-your-own-key configuration through multiple LLM modes selected in settings.yaml / env vars: `openai` (OpenAI key), `openailike` (any OpenAI-compatible endpoint with configurable api_base + api_key, e.g. LM Studio, vLLM, remote proxies), `azopenai` (Azure OpenAI endpoint + key), `gemini` (Google Gemini API key), and `sagemaker`. Users set their own api_key and api_base, so any remote OpenAI-compatible provider can be plugged in. Very popular (~57k stars) and actively maintained (v1.0.1 released June 2026).

Why this trust score (93/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 22/25: The key is supplied by an environment variable or local config file you control.
  • Request Routing 20/20: Requests go straight from you to the AI provider. The provider endpoint is configurable, so you can point it at the provider or your own gateway.
  • Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 7/10: Key handling was found in the published source by BYOAIK's scanner.

What was checked

Verification tier SOURCE_VERIFIED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [STRONG · SOURCE_SCAN] The provider endpoint is configurable, so requests can be pointed straight at the provider or at your own gateway. source
  • [CONFIRMED · SOURCE_SCAN] Ships a container definition, so it can be self-hosted on your own infrastructure. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-14, about 0 month(s) ago. source

How your API key is handled

Your API key is supplied via an environment variable or local config file. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Install the tool, set your provider API key as an environment variable (or in its config file), and pick a model.